Privacy policy
Sinfonie is a desktop application for macOS. It runs on your computer, and almost everything it handles stays there. This page explains the exceptions.
What stays on your Mac
- Your repositories, workspaces, conversations with AI models, notes and settings live in the app’s data folder on your Mac.
- Access tokens for services you connect (Slack, Jira, Linear, GitHub, model providers) are stored on your Mac, encrypted with the macOS keychain (Electron safeStorage). They are used only to talk to that service on your behalf.
- Messages the app reads from Slack, Jira or Linear are kept in the app’s data folder so you can see them again. We never receive them.
What the app sends elsewhere
| Where | What | Why |
|---|---|---|
| AI providers you choose (Anthropic, OpenAI, Google, xAI, or a local model) | The prompts you write, the code and messages you ask about, and, for the on-call assistant, the Slack thread being triaged | To produce answers. Governed by that provider’s terms and your account with them. |
| Slack, Jira, Linear, GitHub | API requests with your token | To read what you asked the app to watch and to post what you approved. |
| sinfonie.dev (our server, hosted on Cloudflare) | The one-time OAuth authorization code during Slack sign-in, kept for at most 10 minutes; anonymous crash reports and a daily usage ping (app version, macOS version, counts) when enabled; feedback you submit | To complete sign-in, and to keep the app working. No message content, tokens, code or repository names are included. |
| GitHub (releases) | A version check | To offer updates. |
| sinfonie.dev, when you sign in with GitHub | Your GitHub id, username, display name, primary email and avatar; a session token for the app | To recognise you and apply your plan. Only needed for paid plans. |
| relay.sinfonie.dev, when you pair a phone | Encrypted envelopes between your Mac and your phone that we cannot read; the room id, which is a hash of a key only your devices hold; push notification text (workspace name, kind of prompt, tool name) and your phone’s push subscription | To let the phone continue conversations and to notify you when an agent waits. Governed by this policy; nothing is stored beyond the phone’s push subscription and a short queue of undelivered messages. |
| Paddle (merchant of record), when you buy a plan | Your payment details and billing address, handled by Paddle; we receive your Paddle customer id and subscription status | To sell and renew paid plans. Governed by Paddle’s privacy policy. |
Slack specifically
- Sinfonie connects to Slack as you, through Slack’s OAuth, with these user scopes:
channels:read,groups:read(list channels),channels:history,groups:history(read the channels you chose to watch),users:read(show names),search:read.public(find related threads),chat:write(post replies). - The app reads only the channels you add to its watch list. It never reads direct messages.
- Nothing is posted to Slack without you pressing Send on that exact message. Drafts written by an AI model are labelled as such and can be edited before sending.
- Your Slack token is stored encrypted on your Mac and never sent to us. Our server holds only the app’s client secret, used to exchange the sign-in code for your token, and forwards Slack’s answer to your Mac without storing it.
- Disconnecting Slack in the app deletes the token from your Mac. You can also revoke Sinfonie from your Slack workspace settings at any time.
Crash reports and usage
Crash reports and the daily usage ping can be turned off in Settings → Feedback & diagnostics. They contain no conversation content, code, tokens or personal data beyond a random install id.
Data retention and deletion
Deleting the app’s data folder on your Mac removes everything it stored. Crash reports, usage pings and feedback on our server are kept for up to 12 months. Write to [email protected] to have them removed.
Changes
We will update this page when the app’s behaviour changes, and note the effective date at the top.